This topic describes the billable items, overdue payments, expiration policy, and refund policy of the subscription billing method for Anti-DDoS Native 2.0.
Selection guide
Select an instance
Anti-DDoS Native 2.0 (Subscription) provides the following instance types, each available in Insurance mode and Unlimited mode:
Anti-DDoS Native (SMB): Select this instance if your public IP assets are in the same region, the number of IPs is 30 or fewer, and the business bandwidth does not exceed 1,000 Mbit/s. This edition supports only standard cloud assets and does not allow Advanced EIPs.
Enterprise: Select this instance if your public IP assets span multiple regions, the number of IPs exceeds 30, or your assets include both IPv4 and IPv6 addresses. This edition supports both standard and enhanced cloud products, with the latter requiring Advanced EIPs.
If you deploy services outside the Chinese mainland, we recommend Anti-DDoS Native (Advanced) EIP or Anti-DDoS Proxy (Outside Chinese Mainland). To use Anti-DDoS Native 2.0 (Subscription) instead, contact your pre-sales account manager.
To purchase the Anti-DDoS Native (SMB) edition in Unlimited mode or the Enterprise edition in Insurance mode, contact your pre-sales account manager.
Advanced EIP assets are automatically assigned to the Anti-DDoS Native 2.0 (Subscription) instance. If a pay-as-you-go instance exists when you purchase a new Advanced EIP, that EIP is preferentially assigned to the pay-as-you-go instance.
Item | Anti-DDoS Native (SMB) | Enterprise | ||
Insurance Mode | Unlimited Mode | Insurance Mode | Unlimited Mode | |
Mitigation sessions | 2 sessions/month Note After all mitigation sessions are consumed, your cloud assets retain only Anti-DDoS Basic mitigation capacity. | Unlimited sessions | 2 sessions/month Note After all mitigation sessions are consumed, your cloud assets retain only Anti-DDoS Basic mitigation capacity. | Unlimited sessions |
Mitigation capabilities | Varies by region. For more information, see Regional mitigation capabilities. | Varies by region. For more information, see What is Anti-DDoS Native. | ||
Protected asset types | Standard cloud products | Standard and advanced cloud products | ||
Network protocol types of public IP assets to protect | An instance protects only one of IPv4 or IPv6. | An instance can protect both IPv4 and IPv6 assets. | ||
Number of regions for asset protection | 1 | An instance can protect assets that are assigned public IP addresses in all regions in the Chinese mainland. | ||
Number of IPs supported for protection | Select 1 to 29 when you purchase an instance. | Select 30 to 2,000 when you purchase an instance. For higher specifications, contact your account manager. | ||
Business bandwidth supported for protection | Select 50 to 1,000 Mbit/s when you purchase an instance. | Select any bandwidth with unlimited scale-up, starting at 100 Mbit/s. | ||
Elastic Business Bandwidth | Supports elastic resource usage and uses a daily 95th-percentile billing model by default. For more information, see Pay-as-you-go > Daily 95th percentile metering method. When enabled, the total business bandwidth becomes 5 times the baseline business bandwidth. | |||
SLS logs | Not supported. | Supported. | ||
Multi-account management | Not supported. | Supported. | ||
Business bandwidth selection
Estimate your service traffic and select an appropriate clean bandwidth when you purchase an instance.
Anti-DDoS measures traffic based on per-minute peak values, which may differ from the statistics shown in other cloud product metrics. The estimation method described here is intended only as a reference for selecting business bandwidth and should not be used as a billing standard.
The system samples bandwidth at 5-minute intervals for both inbound and outbound traffic. For each sample, the higher of the two values is used as the bandwidth for that point. At the end of the month, the system sorts all sample points in descending order, discards the top 5%, and uses the highest remaining value as the estimated bandwidth (the 95th percentile).
The following figure illustrates how estimated bandwidth is calculated over a 30-day period.
Upgrade
The following upgrade scenarios are based on mitigation sessions and supported regions. You can also upgrade the business bandwidth and number of IPs as needed.
Anti-DDoS Native (SMB) (Insurance Mode)
Choose this edition and mode when you need more than two mitigation sessions per month.
To protect public IP assets across multiple regions, upgrade to the Enterprise edition in either Unlimited or Insurance mode.
For advanced cloud assets, upgrade to the Enterprise edition in either Unlimited or Insurance mode. Anti-DDoS Native (SMB) currently does not support Advanced EIPs.
Anti-DDoS Native (SMB) (Unlimited Mode)
To protect public IP assets across multiple regions, upgrade to the Enterprise edition in Unlimited mode.
For advanced cloud assets, upgrade to the Enterprise edition in Unlimited mode.
Enterprise (Insurance Mode)
If you need more than 2 mitigation sessions per month, upgrade to the Enterprise edition in Unlimited mode.
Anti-DDoS Native (SMB) in Unlimited mode and Enterprise in Insurance Mode are available only for instance upgrades. To purchase a new instance in either of these editions or modes, contact your account manager.
Billing
Total instance fee = Subscription fee (protection feature fee + business bandwidth fee + IP quantity protection fee) + Pay-as-you-go fee (elastic business bandwidth fee).
The total cost of an instance includes subscription fees and pay-as-you-go fees. Be sure to also review the Pay-as-you-go tab.
The Enterprise supports Advanced EIP assets. Standard cloud assets and Advanced EIP assets have the same pricing (traffic, IP count, and feature fees) on subscription instances.
Subscription
Protection fee
The basic fee for using the instance. The unit price varies based on the instance protection mode.
Instance protection mode
Unit price(USD/month)
Anti-DDoS Native (SMB) (Insurance Mode)
1,950
Enterprise (Unlimited Mode)
6,000
Bandwidth fee
Instance protection mode
Unit price(USD/month/Mbps)
Anti-DDoS Native (SMB) (Insurance Mode)
Enterprise (Insurance Mode)
5
Anti-DDoS Native (SMB) (Unlimited Mode)
Enterprise (Unlimited Mode)
10
IP quantity protection fee
Charged based on the number of protected asset IPs using tiered pricing. The unit price varies by instance protection mode. If the IP count in the following table does not meet your requirements, contact your account manager.
Instance protection mode
Number of IPs
Unit price(USD/month/instance)
Anti-DDoS Native (SMB) (Insurance Mode, Unlimited Mode)
[0, 100]
24
Enterprise (Insurance Mode, Unlimited Mode)
[0, 30]
0
(30, 100]
24
(100, 300]
19.2
(300, 500]
14.4
(500, 700]
12
(700, 1,000]
9.6
For example, if you purchase an Enterprise (Unlimited Mode) instance with 200 IPs, the IP quantity protection fee is calculated as follows:
For the 30 IPs within the [0, 30] range, the monthly fee is 0 USD.
For the 70 IPs within the (30, 100] range, the monthly fee is 24 x 70 = 1,680 USD.
For the 100 IPs within the (100, 300] range, the monthly fee is 19.2 x 100 = 1,920 USD.
Therefore, the monthly fee for the protected IPs is 1,680 + 1,920 = 3,600 USD.
Pay-as-you-go
Pay-as-you-go includes only the elastic business bandwidth fee.
Daily 95th percentile billing is the default and only metering method for elastic business bandwidth. The business bandwidth increases elastically by 4 times the baseline, making the total business bandwidth 5 times the baseline. For example, if the baseline is 1 Gbit/s, the total business bandwidth is 5 Gbit/s.
When actual traffic exceeds the baseline business bandwidth, traffic is not rate-limited, but additional charges apply for the excess. When actual traffic stays within the baseline, no additional pay-as-you-go fees are incurred. You can query elastic business bandwidth usage in the Billing Center.
Starting from 10:00 on May 28, 2026, Anti-DDoS Native no longer supports the monthly 95th percentile billing mode for elastic business bandwidth. Both new and existing customers will have the daily 95th percentile billing enabled by default. Additionally, manual configuration of elastic business bandwidth in the console (such as disabling or enabling the feature, changing the billing mode, or adjusting bandwidth specifications) is no longer supported. For more information, see [Important] Adjustments to Anti-DDoS burstable billing feature.
Disabling daily 95th-percentile billing takes effect the next day and can be done only once per month.
Billing mode | Unit price | Cost calculation formula |
Daily 95th percentile | USD 1.79/day/Mbit/s | Billable bandwidth x Unit price How to calculate the billable bandwidth
|
Monthly 95th percentile | USD 12.5/month/Mbit/s | Billable bandwidth × Validity factor × Unit price
|
Billing generation and settlement times are as follows. Actual times are subject to the system.
Billing mode | Billing generation time | Settlement time |
Daily 95th percentile | At approximately 10:00 the next day, the elastic business bandwidth bill for the previous calendar day is sent to the Alibaba Cloud account contact via text message, email, and internal message. | At approximately 16:00 the next day, Alibaba Cloud pushes the elastic business bandwidth usage and deducts the corresponding fees from the account balance. |
Monthly 95th percentile | At approximately 10:00 on the first day of the following month, the elastic business bandwidth bill for the previous calendar month is sent to the Alibaba Cloud account contact via text message, email, and internal message. | At approximately 11:00 on the third day of the following month, Alibaba Cloud pushes the elastic business bandwidth usage and deducts the corresponding fees from the account balance. |
Mitigation session consumption
Calculation method: Traffic is recorded at 5-second intervals (12 data points per minute). When attack traffic exceeds N Gbit/s, the system starts accumulating the attack duration (shown as X+Y in the figure). Every 15 minutes (180 data points) of accumulated attack duration consumes one full protection session. For information on how to check your remaining sessions, see Manage instances.

In the figure, the red line represents the inbound traffic of the protected public IP asset.
For public IP assets in the Chinese mainland: N = 20 Gbit/s.
For public IP assets outside the Chinese mainland: N = 10 Gbit/s.
Example: An asset located in Chinese Mainland is under attack. The instance has 2 protection sessions.
First attack: Duration exceeding 20 Gbit/s is 10 minutes.
Second attack: Duration exceeding 20 Gbit/s is 12 minutes.
Total cumulative duration: 22 minutes.
Session consumption process:
First session consumption:
During the second attack, when the cumulative attack duration reaches 15 minutes (10 minutes from the first attack + 5 minutes from the second), the first protection session is consumed. The remaining 7 minutes of the second attack (22 - 15 = 7) are carried forward to the next counting cycle.Second session consumption:
If attacks continue within the same month, the carried-forward 7 minutes will accumulate with any new attack duration. When the cumulative duration in this new cycle reaches 15 minutes, the second protection session is consumed.
Bandwidth limit and overage recovery
Bandwidth limit
Enhanced cloud assets have the following bandwidth limits based on region. Standard cloud assets do not have these limits:
Access scenario | Chinese Mainland | Outside Chinese Mainland |
Local access | 20 Gbit/s | 2 Gbit/s |
Cross-region access | Unlimited | 100 Mbit/s |
Bandwidth overage recovery
Overage alerts and mitigation downgrade: Anti-DDoS Native allows business traffic to temporarily exceed the instance bandwidth. When the cumulative monthly overage duration reaches 1 hour, 9 hours, 18 hours, 27 hours, or 36 hours, the system sends a notification through Message Center the next morning (T+1). When the cumulative overage duration reaches 36 hours, Anti-DDoS Native protection is disabled and only Basic protection remains.
Three ways to restore Anti-DDoS Native protection: If protection has been disabled, you can restore it using one of the following methods:
Method 1: Wait for automatic recovery at 00:00 on the 1st of the next month. No action is required.
Method 2: Enable elastic business bandwidth (Anti-DDoS Native 2.0 Enterprise subscription instances only). Protection is restored immediately after enabling. The bandwidth limit increases to 5 times the baseline bandwidth (adding 4 times as elastic bandwidth).
Method 3: Upgrade the baseline bandwidth of your instance. Protection is restored immediately after the upgrade.
Overage accumulation rules after recovery: After restoring protection using method 2 or 3, the overage handling rules for the remainder of the month are as follows:
If 36 hours were already accumulated before recovery: If overage occurs again after recovery, you receive an alert the next day (T+1) and protection is disabled again.
If less than 36 hours were accumulated before recovery: Overage duration continues to accumulate after recovery. If the total cumulative duration reaches 36 hours for the month, you receive an alert the next day (T+1) and protection is disabled.
Expiration information
Time period | Impact after expiration | Instance configuration |
Within 7 days (inclusive) after expiration | Service stops immediately after expiration. Service is restored after you renew the instance. | Instance configuration is retained. |
On the 8th day after expiration |
|
|
Refund policy
Refunds are not supported after you purchase an instance.
Traffic charges are covered by a charge protection mechanism. In rare cases, attack traffic may be counted as clean traffic (for example, HTTP GET Flood attacks may cause abnormal outbound traffic increases). In such cases, you can contact technical support to request a reduction or waiver of the abnormal charges on your traffic bill.
NoteProvide supporting materials such as server logs or traffic monitoring data (for example, normal and abnormal QPS logs during an HTTP GET Flood attack) to help Alibaba Cloud identify and resolve abnormal charges more quickly.
Payment Overdue
Your account is considered overdue when the available balance (including cash, vouchers, and coupons) cannot cover outstanding bills.
Service stops immediately upon overdue. After 15 days of suspension, the instance is released and all configurations are permanently deleted and cannot be recovered.
To avoid service interruption from overdue payments, enable auto-renewal. For more information, see Renewal.
Query
Bill query: You can query bills in the Expenses and Costs console.
Bills generated on day T are typically pushed on day T+1. For large bills, Alibaba Cloud may perform a secondary review and delay the push by 1 to 3 days, combining multiple days of bills.
Usage query: Log on to Traffic Security console and view your usage on the page.
FAQ
Why does the traffic data in Cloud Monitor and other cloud product metrics differ from the Anti-DDoS traffic data?
Traffic metrics displayed in the Anti-DDoS console are typically higher than those shown in Cloud Monitor or other specific cloud product pages.
Example scenario:
When an ECS instance undergoes a DDoS attack that triggers traffic scrubbing, the Anti-DDoS Basic notification may report a trigger threshold of 2.5 Gbit/s. However, a query in Cloud Monitor for the same period might show an inbound bandwidth of only 1.2 Git/s on the EIP associated with the ECS instance.
This discrepancy arises from three main factors:
Measurement stage (pre-scrubbing vs. post-scrubbing)
Anti-DDoS data: Captured before traffic scrubbing. It includes all incoming traffic, comprising both legitimate business traffic and malicious attack traffic.
Cloud Monitor data: Captured after traffic scrubbing. It reflects only the legitimate traffic that has been filtered and forwarded to the instance, as attack traffic is discarded during the scrubbing process.
Monitoring granularity (second-level vs. minute-level)
Anti-DDoS: Utilizes second-level granularity to detect attacks, allowing it to capture instantaneous traffic spikes accurately.
Cloud Monitor: Typically aggregates EIP traffic data at minute-level intervals. Consequently, instantaneous peaks may be smoothed out in the average, resulting in lower reported values compared to real-time spikes.
Monitoring location (network boundary vs. forwarding device)
Anti-DDoS: Monitors traffic at the boundary between the Internet and the Alibaba Cloud network, recording all raw inbound traffic.
Cloud Monitor: Collects data from forwarding devices closer to the instance, recording only the traffic successfully delivered to the resource.
All public cloud IaaS products, such as ECS, SLB, EIP, and NAT Gateway, may encounter the preceding issue.